Government security, Zero trust

NSA guidance sets phased approach for zero trust adoption

Zero Trust

Infosecurity Magazine reports that the National Security Agency has released new Zero Trust Implementation Guidelines outlining how organizations can advance toward target-level zero trust maturity, aligning with the governments broader cybersecurity strategy.

Included in the guidance are two ZIG phases meant to support the Defense Department and zero trust framework, as well as the federal cybersecurity strategy, with Phase One defining 36 activities supporting 30 zero trust capabilities to establish a secure baseline and Phase Two adding 41 activities tied to 34 additional capabilities across component environments. The phased structure is modular rather than a fixed roadmap, allowing organizations to tailor adoption based on operational needs and constraints.

"Any zero trust architecture that leaves visibility and management of the application policy decision points out of the architecture is expensive and grossly insufficient," said AppOmniCTO and Co-Founder Brian Soby.

The guidelines emphasize continuous authentication and authorization after login, reflecting concerns raised about attacks that occur post-authentication. Developed in coordination with the Defense Department CIO, the framework organizes 152 zero trust activities, with the NSA noting that additional advanced phases could be developed in the future.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Asymmetric Warfare

You can skip this ad in 5 seconds